T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/fetch_usage.py:38- Finding
Overbroad Browser Snapshot Access Violates Least Privilege
- Content
View full analysis
Vulnerability Details
File Location:
scripts/fetch_usage.py:38-53
Vulnerability Type: Browser access scope violation
Risk Level: Mediumpython # Alternative: look for targetId pattern import re matches = re.findall(r'targetId["\']?\s*:\s*["\']?([A-F0-9]+)', tabs_output) # Try each targetId until we find the Kimi tab for target_id in matches: snap_result = subprocess.run( ["openclaw", "browser", "snapshot", "--target-id", target_id], capture_output=True, text=True, timeout=30 ) if snap_result.returncode == 0 and "kimi.com" in snap_result.stdout.lower(): kimi_tab_id = target_id snapshot = snap_result.stdout breakTechnical Analysis
The Skill only needs to read quota information from the Kimi console. However, it extracts every target ID returned by
openclaw browser tabsand requests a complete snapshot of each target until snapshot text contains the stringkimi.com.The implementation does not associate a tab's URL with its corresponding target ID before requesting the snapshot. Consequently, unrelated attached tabs may be read before the Kimi tab is found. These tabs can include authenticated email, internal applications, account pages, or other private browser content.
Testing whether snapshot content contains
kimi.comis not a reliable origin validation mechanism. An unrelated page can contain that string in visible text, causing it to be misidentified as the Kimi console. The code does not transmit captured snapshots to an external destination, but reading them still exceeds the minimum privileges required by the declared functionality.Attack Path
- The user has multiple browser tabs exposed through the OpenClaw browser integration.
- One or more unrelated authenticated or sensitive tabs appear before the actual Kimi console target in the returned target-ID sequence.
- The Skill invokes `o ...[truncated 977 chars]
- Remediation
View remediation
Remediation Suggestions
- Parse the browser tab listing as structured data rather than extracting every target ID with a global regular expression.
- Associate each target ID with its tab URL before requesting any snapshot.
- Normalize and parse the URL, then require the hostname to be exactly
kimi.comor an explicitly approved Kimi subdomain. - Require the expected console path, such as
/code/console, where practical. - Snapshot only the single validated Kimi target.
- Validate the selected target through trusted browser metadata rather than searching rendered page content for a domain string.
- Reject malformed, ambiguous, or duplicate tab-list results instead of scanning all tabs.
- Avoid logging raw snapshots and ensure subprocess buffers containing browser content are discarded promptly.
